Cybersecurity by department
Every area of your company has its part — and its risk. Here's what each one needs to be NIS2-ready, and how we set it up from Tria, speaking their language.
Cybersecurity is cross-functional. It isn't solved inside one department: it holds up through the joint work of all of them. A single open door —in any area— is enough to compromise the whole company.
Department
Whoever leads is who answers
This is what's at stake in the boardroom, what you need under control to be NIS2-ready, and how we set it up from Tria.
Cybersecurity is fully delegated to IT and management doesn't oversee it. If there's an incident or an inspection, no one answers with judgment or can prove anything was decided.
◆ In a NIS2-ready setup, the management body is responsible for approving and overseeing the measures.
Take on oversight: approve the policies, review risk regularly and assign owners and resources.
A management that doesn't understand the risk decides blindly and can't demonstrate due diligence.
◆ Training of the management bodies is an explicit requirement in NIS2.
Specific, non-technical training: what your obligations are, what to ask and how to read risk.
You invest blindly —or not at all— and buy tools that don't reduce real risk.
A risk-prioritised plan and a defensible budget, tied to business impact.
In a serious incident, accountability falls on management and can't be fully passed on. Without evidence of diligence, you're exposed to the fine.
Being able to prove you did what was reasonable: documented decisions, a response plan and timely notification.
When something happens, no one knows who decides what; you improvise in front of clients and media and lose time and money.
A continuity and crisis plan with management inside: what stops, who decides and what's communicated.
An incident —or not being able to prove your level— closes contracts and damages the brand. Large clients already demand guarantees.
Turning security into an argument: proving your level to clients and in tenders.
Department
Who keeps operations running
We're not here to teach you your job: we give you the prioritised framework, evidence ready to go and take the documentation load off you. This is what to have NIS2-ready.
Shared accounts, weak passwords, ex-employees with access, admins with no control. A stolen login is the direct way in.
Identity and access under control: MFA, least privilege, fast joiners/leavers and periodic review.
Backups that aren't tested or with no offline copy. Against ransomware, there's no way back.
3-2-1 backups with tested restores and defined recovery times (RTO/RPO).
Unpatched systems exposed to the internet. Known flaws get exploited.
Inventory, patching and vulnerability management prioritised by criticality.
An attacker gets in and no one notices for weeks. Without logs there's no way to know what happened.
Centralised logs, alerts and the ability to detect and respond.
A flat network (everything connected to everything) and unprotected email: phishing and lateral movement.
Segmentation, email protection and safe browsing.
Everything works but you can't prove it. Audits and clients ask for evidence that doesn't exist.
Document the controls and leave traceable evidence.
Department
Who looks after people
You handle the most sensitive data and you're key against fraud. This is what to keep under control and how we set it up, without slowing your day-to-day.
Payroll, health and candidate data accessible too widely. A leak here is serious and highly fineable.
Minimum access, clear retention periods and legal basis.
Whoever leaves still has access; whoever joins gets it late or too broad.
Onboarding and offboarding with real access provisioning and revocation.
The team is the number-one way in; one click takes the company down.
Ongoing training and simulations to reduce human error.
A missing or poorly run channel exposes the company and whistleblowers.
◆ A whistleblowing channel is mandatory for many companies (Spanish Law 2/2023).
A secure, confidential and well-run channel.
Monitoring without informing or disproportionately leads to fines and conflict.
Informing and keeping control proportionate (access, cameras, devices).
Security is seen as a brake and the team dodges it.
Making security part of the culture, not a punishment.
Department
The direct target of fraud
You're where the money is, and that makes you the preferred target. This is what to reinforce and how we set it up so fraud doesn't get through.
Fake emails ordering urgent transfers or account changes. Just one that gets through and the money is gone.
Double verification of payments and of bank-detail changes.
Access to banking and payment data with no control; credential theft.
Restricted access, MFA on banking and protection of payment data.
If the system goes down, you can't invoice, collect or pay. The business stops.
Continuity of critical financial processes.
Non-compliant or tamperable invoicing systems.
Compliant, complete and traceable invoicing.
You pay for cyber insurance that doesn't cover what you think, or you don't size the investment.
Sizing the investment and understanding the real coverage.
Dependence on payment platforms and third parties with no control.
Assessing the security of financial third parties.
Department
Who answers on paper
We don't replace you: we give you the technical and organisational side that holds up the legal work. Evidence, analysis and traceability so nothing falls through the cracks.
Processing with no legal basis, no register and no control. A breach or an inspection catches you without paperwork.
A living, demonstrable data-protection programme.
Suppliers processing your data with no contract or guarantees: you answer for it.
◆ NIS2 extends the security requirement to the whole supplier chain.
Processor contracts and guarantees with whoever touches your data.
In a breach, failing to notify in time multiplies the fine.
◆ Breach notification has strict deadlines (72 h).
A detection, assessment and timely-notification procedure.
Not knowing which framework applies to you (NIS2 / ENS / DORA) or how to prove it.
Knowing your obligation and holding the evidence that backs it.
A missing or non-compliant channel.
A compliant, confidential and managed channel.
In an inspection, evidence of diligence is missing.
A ready, traceable file.
Department
The supply-chain door
An insecure supplier is your way in, and you're the supplier others audit. This is what to control in both directions.
An insecure supplier is your way in: their breach is your breach.
◆ NIS2 makes you responsible for the security of your supply chain.
Knowing and controlling your suppliers' risk.
Contracts with no security clauses or defined responsibilities.
Security clauses and service levels in contracts.
Suppliers with broad, permanent access to your systems.
Minimum, temporary and reviewed access.
Depending on a cloud / SaaS with no plan B: if it falls, you fall.
Assessing concentration and having alternatives.
Requiring security slows procurement and annoys the business.
A proportionate, fast vetting process.
A large client audits you and you have no answers: you lose the contract.
Having your own evidence ready for when you're audited.
Department
Who can't stop
An incident here isn't an IT problem: it's a delivery and deadline problem. This is what to secure so operations hold.
An incident stops production or the service and you miss client deadlines.
Knowing which processes can't stop and how to sustain them.
There's no inventory of what's critical; you protect blindly.
Identifying and prioritising critical assets and processes.
Machinery and industrial systems connected and unprotected.
Segmenting and protecting the OT environment (where applicable).
When it happens, you improvise and take long to recover.
A response and operational-recovery plan.
Dependence on logistics and service providers: their failure stops you.
Continuity in the chain that supplies you too.
Loss or tampering of production or order data.
Integrity and backups of operational data.
Department
The heavy data user
Your CRM and prospecting tools are pure personal data. This is what to tidy up to capture leads without fines — and how to turn compliance into a sales argument.
The whole CRM is personal data; a breach exposes your entire client base.
Legal basis, access and CRM cleanup.
Buying or enriching lists with no control is a high fine risk.
Prospecting with a legal basis and traceability of the data's origin.
Sending commercial communications without valid consent.
Consent and opt-outs handled correctly.
A site with non-compliant cookies and forms: the first thing an inspection looks at.
Compliant cookies, forms and notices.
Dozens of tools (ads, email, analytics) processing data with no control.
Knowing which tools process data and with what guarantees.
Losing sales for not being able to prove security — or not leveraging it when you have it.
Using compliance as a commercial lever.
The free check-up tells you in 2 minutes what applies to you and where to begin. No sign-up, no data required.
Take the free check-up →